Services Based Pentest Checklist
Symfony PHP
/app_dev.php
/app_dev.php/_profiler
/_profiler
/_profiler/latest
/_profiler/search
/_profiler/phpinfo
/_profiler/{token}
/_wdt/{token}
/app_example.php
/app_test.php
/index_dev.php
/config.php
/_configurator/
/_configurator/steps
/_configurator/step/{index}Laravel
WordPress
Django
Rails
Express.js / Node.js
Flask
GraphQL
Next.js
Strapi
Spring Boot
ASP.NET
PHP General
Apache
Nginx
Tomcat
Kibana
Elasticsearch
MongoDB
Redis
Docker
General Misconfig Checks
Postman API Platform
Salesforce
Trello
Figma
Freshworks Freshservice
Slack
Atlassian Bitbucket
Atlassian Confluence
Atlassian Jira
AWS S3
Cloudflare R2
Google Groups
Google Docs
Google Cloud Storage Bucket
Google OAuth
Jenkins
GitLab
Drupal
Automation
Last updated
